CLEAN MX realtime database
public access query for virus URL statistics
Totally watched: 20263, to down: 0, to up: 0, changed ip: 0
As of 2010-09-02 21:05:38 CEST
Subscribe to the VirusWatch Mailing list, updated hourly

This database consists of Virus URI, collected and verified since Feb 2006

If you detect URI'S concerning your netblock, already closed... you have made a good job, otherwise please close them as soon as possible.

to look at some nice charts, there are complete statisticsstatistics for this database
Attention: all URI'S are manually verified, but not cross-checked for real viruses function in this moment you make this query.(Sites may have been closed already..)
Our automatic Viruswalker process is scheduled every hour, so you may see now a incident and this one will be resolved later on.
So please keep on sending close-feedbacks to us...

if you have questions, criticism, wishes or ... do not hesitate to contact us at abuse@clean-mx.de
Our PBX is down you may reach us by cell phone +49 171 4802507 ...
Query as xml: Same query as xml output
TIMERS: Runtime Query: 0.0231 Seconds
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
1 637717 2010-08-18 09:55:50 2010-08-18 10:13:40 0.3 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/add1.txt?t=0.343126 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 18 2010 10:13:40 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/add1.txt?t=0.343126 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/add1.txt?t=0.343126 ...
2 637718 2010-08-18 09:55:50 2010-08-18 10:13:35 0.3 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/bll2.txt?t=0.895136 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 18 2010 10:13:35 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/bll2.txt?t=0.895136 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/bll2.txt?t=0.895136 ...
3 637719 2010-08-18 09:55:50 2010-08-18 10:13:31 0.3 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/ctt3.txt?t=0.135050 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 18 2010 10:13:31 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/ctt3.txt?t=0.135050 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/ctt3.txt?t=0.135050 ...
4 631762 2010-08-03 18:19:34 2010-08-03 19:07:27 0.8 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/alk1.txt?t=0.643735 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 03 2010 19:07:27 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/alk1.txt?t=0.643735 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/alk1.txt?t=0.643735 ...
5 631763 2010-08-03 18:19:34 2010-08-03 19:07:23 0.8 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/bgd2.txt?t=0.547529 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 03 2010 19:07:23 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/bgd2.txt?t=0.547529 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/bgd2.txt?t=0.547529 ...
6 631764 2010-08-03 18:19:34 2010-08-03 19:07:19 0.8 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ckr3.txt?t=0.272186 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 03 2010 19:07:18 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ckr3.txt?t=0.272186 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ckr3.txt?t=0.272186 ...
7 631765 2010-08-03 18:19:34 2010-08-03 19:07:14 0.8 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ewx5.txt?t=0.698564 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 03 2010 19:07:14 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ewx5.txt?t=0.698564 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ewx5.txt?t=0.698564 ...
8 630955 2010-08-02 10:18:34 2010-08-02 11:11:00 0.9 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.2 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 02 2010 11:11:00 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.2 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.2 ...
9 630956 2010-08-02 10:18:34 2010-08-02 11:10:56 0.9 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.214534 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 02 2010 11:10:55 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.214534 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.214534 ...
10 630583 2010-08-01 18:58:59 2010-08-01 19:07:03 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.7 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 01 2010 19:07:03 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.7 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.7 ...
11 630584 2010-08-01 18:58:59 2010-08-01 19:06:58 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.349773 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 01 2010 19:06:58 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.349773 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.349773 ...
12 630585 2010-08-01 18:58:59 2010-08-01 19:06:54 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/alk1.txt?t=0.343609 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 01 2010 19:06:54 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/alk1.txt?t=0.343609 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/alk1.txt?t=0.343609 ...
13 630586 2010-08-01 18:58:59 2010-08-01 19:06:49 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/bgd2.txt?t=0.553647 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 01 2010 19:06:49 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/bgd2.txt?t=0.553647 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/bgd2.txt?t=0.553647 ...
14 630587 2010-08-01 18:58:59 2010-08-01 19:06:45 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ckr3.txt?t=0.267943 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 01 2010 19:06:45 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ckr3.txt?t=0.267943 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ckr3.txt?t=0.267943 ...
15 630588 2010-08-01 18:58:59 2010-08-01 19:06:40 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ewx5.txt?t=0.706948 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt August 01 2010 19:06:40 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ewx5.txt?t=0.706948 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ewx5.txt?t=0.706948 ...
16 629997 2010-07-31 09:17:58 2010-07-31 10:04:45 0.8 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.951610 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 31 2010 10:04:44 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.951610 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.951610 ...
17 629336 2010-07-29 23:05:17 2010-07-30 00:08:44 1.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/kb.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 30 2010 00:08:44 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/kb.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/kb.txt
18 629337 2010-07-29 23:05:17 2010-07-30 00:08:40 1.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.2 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 30 2010 00:08:40 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.2 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.2 ...
19 629338 2010-07-29 23:05:17 2010-07-30 00:08:36 1.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/add1.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 30 2010 00:08:35 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/add1.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/add1.txt
20 629339 2010-07-29 23:05:17 2010-07-30 00:08:31 1.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/bll2.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 30 2010 00:08:31 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/bll2.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/bll2.txt
21 629340 2010-07-29 23:05:17 2010-07-30 00:08:26 1.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/ctt3.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 30 2010 00:08:26 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/ctt3.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/ctt3.txt
22 629341 2010-07-29 23:05:17 2010-07-30 00:08:22 1.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/dll4.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 30 2010 00:08:22 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/dll4.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns2.zonomi.com follow up this item ns1.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/vmw/dll4.txt
23 623294 2010-07-19 08:11:22 2010-07-19 09:23:17 1.2 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/byt.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 19 2010 09:23:17 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/byt.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/byt.txt
24 623244 2010-07-19 07:22:15 2010-07-19 08:12:26 0.8 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.5 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 19 2010 08:12:26 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.5 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/install2.exe?t=0.5 ...
25 623245 2010-07-19 07:22:15 2010-07-19 08:12:22 0.8 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.665477 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 19 2010 08:12:22 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.665477 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.665477 ...
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
26 617984 2010-07-08 08:10:31 2010-07-08 08:16:51 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/bgd2.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 08 2010 08:16:51 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/bgd2.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/bgd2.txt
27 617985 2010-07-08 08:10:31 2010-07-08 08:16:46 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ckr3.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 08 2010 08:16:46 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ckr3.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/ckr3.txt
28 617986 2010-07-08 08:10:31 2010-07-08 08:16:42 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/dpn4.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 08 2010 08:16:42 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/dpn4.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/dpn4.txt
29 617981 2010-07-08 08:10:31 2010-07-08 08:17:05 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/faq.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 08 2010 08:17:04 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/faq.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/faq.txt
30 617982 2010-07-08 08:10:31 2010-07-08 08:17:00 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.586361 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 08 2010 08:17:00 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.586361 ... follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/temp/reg.exe?t=0.586361 ...
31 617983 2010-07-08 08:10:31 2010-07-08 08:16:56 0.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/alk1.txt  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 08 2010 08:16:55 CEST. SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(ip) in same window 89.248.162.210 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.210 at Rus CERT university stuttgart germanylookup 89.248.162.210 at Ripefollow up this item(review) in same window 89.248.162.210 Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/alk1.txt follow up this domain(mejac.com) mejac.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.zonomi.com follow up this item ns2.zonomi.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mejac.com/xcc/alk1.txt
32 517524 2010-04-15 13:15:39 2010-04-15 18:12:16 4.9 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (unknown_html_google_malware) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(unknown_html_google_malware) for scanner (undef) in md5 table unknown_html_google_malware
Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/bin2.exe  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt April 15 2010 18:12:15 CEST. SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(ip) in same window 89.248.162.197 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(review) in same window 89.248.162.197 Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/bin2.exe follow up this domain(89.248.162.197) 89.248.162.197 follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/bin2.exe
33 502781 2010-04-06 15:59:30 2010-04-17 10:48:48 258.8 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
0/39 (0.00%) 
 Virustotal.
MD5:
4b1093a6b4ccb13b9d20328aed3544ca
 
 lookup in virustotal.com (4b1093a6b4ccb13b9d20328aed3544ca)-->[http://www.virustotal.com/analisis/f5e82608c19e30284783fd8b9e65aca975671430751eb163d33c7638225fcaaf-1270565011]follow up this md5sum(4b1093a6b4ccb13b9d20328aed3544ca)follow up this itemfollow up this virusname (unknown_html_google_malware) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(unknown_html_google_malware) for scanner (undef) in md5 table0/39 (0.00%) unknown_html_google_malware
Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/nv/nv.php  up Saved evidence (63 Bytes) of first contact as txt April 06 2010 16:42:57 CEST.No evidence recorded deadSaved log of last contact as txt April 17 2010 10:48:47 CEST. SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(ip) in same window 89.248.162.197 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(review) in same window 89.248.162.197 Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/nv/nv.php follow up this domain(89.248.162.197) 89.248.162.197 follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/nv/nv.php
34 462066 2010-03-20 08:01:20 2010-03-13 08:07:53   follow up this itemfollow up this contributor (sub8) as RSS-Feed sub8possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (Trojan-Dropper.Win32.Delf.exl) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(Trojan-Dropper.Win32.Delf.exl) for scanner () in md5 table Trojan-Dropper.Win32.Delf.exl
Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt March 13 2010 08:07:53 CET. SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(ip) in same window 89.248.162.197 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(review) in same window 89.248.162.197 Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/ follow up this domain(89.248.162.197) 89.248.162.197 follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/
35 467460 2010-03-19 09:03:13 2010-03-25 08:44:35 143.7 follow up this itemfollow up this contributor (sub9) as RSS-Feed sub9possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
16/40 (40.00%) 
 Virustotal.
MD5:
4db9af2bc7cd16d16ea084cd503e47a8
Packed.Generic.295
Heuristic.LooksLike.Trojan.Agent.B
Trojan.TDss.ABP
 
 lookup in virustotal.com (4db9af2bc7cd16d16ea084cd503e47a8)-->[http://www.virustotal.com/analisis/8613794b9ed4b8a530a85a832ec8f0c107034d6da98f50ee73e5f995e94d12c7-1268986025]lookup in threatexpert.comlookup the sha256(8613794b9ed4b8a530a85a832ec8f0c107034d6da98f50ee73e5f995e94d12c7) in comodo.comfollow up this md5sum(4db9af2bc7cd16d16ea084cd503e47a8)follow up this itemfollow up this virusname (TR%2FTDss.AYHI.13) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagelookup Virusname at avirafollow up this malware(TR%2FTDss.AYHI.13) for scanner (avira) in md5 table16/40 (40.00%) TR/TDss.AYHI.13
Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/1268950276.exe  up Saved evidence (82432 Bytes) of first contact as txt March 18 2010 23:11:23 CET.No evidence recorded deadSaved log of last contact as txt March 25 2010 08:44:35 CET. SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(ip) in same window 89.248.162.197 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(review) in same window 89.248.162.197 Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/1268950276.exe follow up this domain(89.248.162.197) 89.248.162.197 follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/1268950276.exe
36 466545 2010-03-18 13:44:30 2010-04-16 21:45:27 703 follow up this itemfollow up this contributor (sub9) as RSS-Feed sub9possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
26/42 (61.90%) 
 Virustotal.
MD5:
e6374b3fb75065ce8d2f39c6c63f4bba
Trojan.Zbot!gen3
Trojan.Agent.AE.367
a
variant
of
Win32/Spy.Zbot.YP
 
 lookup in virustotal.com (e6374b3fb75065ce8d2f39c6c63f4bba)-->[http://www.virustotal.com/analisis/07a9a1c89846d58b976121da821338ceed402275b06bcb7919b20e2cbaa6f3f6-1268917475]lookup in threatexpert.comlookup the sha256(07a9a1c89846d58b976121da821338ceed402275b06bcb7919b20e2cbaa6f3f6) in comodo.comfollow up this md5sum(e6374b3fb75065ce8d2f39c6c63f4bba)follow up this itemfollow up this virusname (Trojan-Spy.Win32.Zbot%21IK) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(Trojan-Spy.Win32.Zbot%21IK) for scanner (a_squared) in md5 table26/42 (61.90%) Trojan-Spy.Win32.Zbot!IK
Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/update.exe  up Saved evidence (110592 Bytes) of first contact as txt March 16 2010 21:50:22 CET.No evidence recorded deadSaved log of last contact as txt April 16 2010 21:45:26 CEST. SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(ip) in same window 89.248.162.197 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(review) in same window 89.248.162.197 Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/update.exe follow up this domain(89.248.162.197) 89.248.162.197 follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/update.exe
37 465662 2010-03-16 23:16:09 2010-03-25 09:20:59 202.1 follow up this itemfollow up this contributor (sub9) as RSS-Feed sub9possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
9/42 (21.43%) 
 Virustotal.
MD5:
07cccc5ff04ebbe858ef3234cb06b893
Trojan.FakeAV
a
variant
of
Win32/Kryptik.DBX
(Suspicious)
-
DNAScan
 
 lookup in virustotal.com (07cccc5ff04ebbe858ef3234cb06b893)-->[http://www.virustotal.com/analisis/1c3cdb721497aed57b835e9da82f8ee8c248d9bde33fea886843e28097697dc3-1268789962]lookup in threatexpert.comlookup the sha256(1c3cdb721497aed57b835e9da82f8ee8c248d9bde33fea886843e28097697dc3) in comodo.comfollow up this md5sum(07cccc5ff04ebbe858ef3234cb06b893)follow up this itemfollow up this virusname (TR%2FFakealert.ahi) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagelookup Virusname at avirafollow up this malware(TR%2FFakealert.ahi) for scanner (avira) in md5 table9/42 (21.43%) TR/Fakealert.ahi
Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/av.57.15.exe  up Saved evidence (269056 Bytes) of first contact as txt March 16 2010 13:25:18 CET.No evidence recorded deadSaved log of last contact as txt March 25 2010 09:20:59 CET. SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(ip) in same window 89.248.162.197 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(review) in same window 89.248.162.197 Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/av.57.15.exe follow up this domain(89.248.162.197) 89.248.162.197 follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/av.57.15.exe
38 465663 2010-03-16 23:16:09 2010-03-25 09:20:58 202.1 follow up this itemfollow up this contributor (sub9) as RSS-Feed sub9possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
7/42 (16.67%) 
 Virustotal.
MD5:
b60acc8554c48de1df37729d30aea202
Adware.Savenow
Win32:Rootkit-gen
Win32:Rootkit-gen
 
 lookup in virustotal.com (b60acc8554c48de1df37729d30aea202)-->[http://www.virustotal.com/analisis/0eb0150b9292f0e1e3431f1ac03a36bcc4ebd8e06692aa75cd5b104ec1d88912-1268777887]lookup in threatexpert.comlookup the sha256(0eb0150b9292f0e1e3431f1ac03a36bcc4ebd8e06692aa75cd5b104ec1d88912) in comodo.comfollow up this md5sum(b60acc8554c48de1df37729d30aea202)follow up this itemfollow up this virusname (TR%2FDrop.Delf.fbt) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagelookup Virusname at avirafollow up this malware(TR%2FDrop.Delf.fbt) for scanner (avira) in md5 table7/42 (16.67%) TR/Drop.Delf.fbt
Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/bin3.exe  up Saved evidence (339456 Bytes) of first contact as txt March 16 2010 22:05:56 CET.No evidence recorded deadSaved log of last contact as txt March 25 2010 09:20:58 CET. SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(ip) in same window 89.248.162.197 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(review) in same window 89.248.162.197 Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/bin3.exe follow up this domain(89.248.162.197) 89.248.162.197 follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/bin3.exe
39 459311 2010-03-11 11:13:00 2010-03-16 11:13:00 120 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
lookup in virustotal.com (c3db12d49c744a78e850df9f19bfc0aa)follow up this md5sum(c3db12d49c744a78e850df9f19bfc0aa)follow up this itemfollow up this virusname (mdl_malware+calls+home) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(mdl_malware+calls+home) for scanner (undef) in md5 table mdl_malware calls home
Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/dlink/ls.php  up Saved evidence (30 Bytes) of first contact as txt March 11 2010 14:27:32 CET.No evidence recorded deadSaved log of last contact as txt April 09 2010 19:11:20 CEST. SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(ip) in same window 89.248.162.197 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(review) in same window 89.248.162.197 Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/dlink/ls.php follow up this domain(89.248.162.197) 89.248.162.197 follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/dlink/ls.php
40 456694 2010-03-08 19:13:01 2010-03-25 12:45:25 401.5 follow up this itemfollow up this contributor (sub9) as RSS-Feed sub9possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
22/42 (52.38%) 
 Virustotal.
MD5:
50761a7c54bf427792068c7192cca693
Infostealer
Heuristic.LooksLike.Win32.NewMalware.H
Trojan.Generic.KD.456
 
 lookup in virustotal.com (50761a7c54bf427792068c7192cca693)-->[http://www.virustotal.com/analisis/b8b90252e3c2fa1ff3ca0bdb82d9f77ac612d42dea8dd3ecacc62f76989e23cd-1268072554]lookup in threatexpert.comlookup the sha256(b8b90252e3c2fa1ff3ca0bdb82d9f77ac612d42dea8dd3ecacc62f76989e23cd) in comodo.comfollow up this md5sum(50761a7c54bf427792068c7192cca693)follow up this itemfollow up this virusname (TR%2FDrop.Delf.fbt) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagelookup Virusname at avirafollow up this malware(TR%2FDrop.Delf.fbt) for scanner (avira) in md5 table22/42 (52.38%) TR/Drop.Delf.fbt
Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/bin.exe  up Saved evidence (226816 Bytes) of first contact as txt March 06 2010 16:44:10 CET.No evidence recorded deadSaved log of last contact as txt March 25 2010 12:45:25 CET. SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(ip) in same window 89.248.162.197 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.197 at Rus CERT university stuttgart germanylookup 89.248.162.197 at Ripefollow up this item(review) in same window 89.248.162.197 Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/bin.exe follow up this domain(89.248.162.197) 89.248.162.197 follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item  follow up this item  follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://89.248.162.197/bin.exe
41 346218 2010-01-10 17:13:00 2010-02-28 21:46:55 1180.6 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
0/41 (0.00%) 
 Virustotal.
MD5:
2a0ce24f362f08db48520a6b828fd65a
 
 lookup in virustotal.com (2a0ce24f362f08db48520a6b828fd65a)-->[no evidence available]follow up this md5sum(2a0ce24f362f08db48520a6b828fd65a)follow up this itemfollow up this virusname (mdl_redirects+to+fake+av) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(mdl_redirects+to+fake+av) for scanner (undef) in md5 table0/41 (0.00%) mdl_redirects to fake av
Safe Virus-Viewer and Analyser may take a minute to complete http://www.kanakaba.in/counter.js  up Saved evidence (60 Bytes) of first contact as txt January 10 2010 19:23:03 CET.No evidence recorded deadSaved log of last contact as txt February 28 2010 21:46:55 CET. SenderBaselookup 64.20.53.82 at Rus CERT university stuttgart germanylookup 64.20.53.82 at Ripefollow up this item(ip) in same window 64.20.53.82 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS19318) in networks tablefollow up this itemfollow up this AS (AS19318) as RSS-Feed AS19318 SenderBaselookup 89.248.162.147 at Rus CERT university stuttgart germanylookup 89.248.162.147 at Ripefollow up this item(review) in same window 89.248.162.147 Safe Virus-Viewer and Analyser may take a minute to complete http://www.kanakaba.in/counter.js follow up this domain(kanakaba.in) kanakaba.in follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 64.20.32.0 - 64.20.63.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.freedomen.info follow up this item ns2.freedomen.info follow up this item ns3.freedomen.info follow up this item ns4.freedomen.info follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://www.kanakaba.in/counter.js
42 324285 2009-12-17 09:52:29 2009-12-22 21:03:48 131.2 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
0/41 (0.00%) 
 Virustotal.
MD5:
b221f5a1671eafbcd04768a8f319a216
 
 lookup in virustotal.com (f493e551018a2437e7438282dd1a6d82)-->[http://www.virustotal.com/analisis/f99e29c914648d025b77b7d01bdd7358866b06776b6189d06b6027db9e213ea8-1261043999]follow up this md5sum(f493e551018a2437e7438282dd1a6d82)follow up this itemfollow up this virusname (unknown_html) as RSS-Feedfollow up this malware(unknown_html) for scanner (undef) in md5 table0/41 (0.00%) unknown_html
Safe Virus-Viewer and Analyser may take a minute to complete http://winrescueupdate.com/download/winl ...  up Saved evidence (2003504 Bytes) of first contact as txt December 17 2009 10:09:45 CET.Saved evidence (1992752 Bytes) of last contact as txt December 22 2009 17:57:47 CET. closed-10752Saved log of last contact as txt December 22 2009 21:03:41 CET. SenderBaselookup 94.76.245.23 at Rus CERT university stuttgart germanylookup 94.76.245.23 at Ripefollow up this item(ip) in same window 94.76.245.23 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29550) in networks tablefollow up this itemfollow up this AS (AS29550) as RSS-Feed AS29550 SenderBaselookup 89.248.162.147 at Rus CERT university stuttgart germanylookup 89.248.162.147 at Ripefollow up this item(review) in same window 89.248.162.147 Safe Virus-Viewer and Analyser may take a minute to complete http://winrescueupdate.com/download/winl ... follow up this domain(winrescueupdate.com) winrescueupdate.com follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 94.76.192.0 - 94.76.255.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://winrescueupdate.com/download/winl ...
43 302179 2009-12-08 09:17:39 2009-12-18 07:26:10 238.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt December 08 2009 10:18:44 CET.15/41 (36.59%) 
 Virustotal.
MD5:
f521ab4944bdb4f2d9bdc91c8bbd34ca
Trojan.Inject.alxc
a
variant
of
Win32/Kryptik.BFO
Trojan.Generic.2823013
 
 lookup in virustotal.com (f521ab4944bdb4f2d9bdc91c8bbd34ca)-->[http://www.virustotal.com/analisis/f24be0d0013fea154b30cf15df068f3b939d494ff236237ae91f175add1b8db4-1260216729]lookup in threatexpert.comlookup the sha256(f24be0d0013fea154b30cf15df068f3b939d494ff236237ae91f175add1b8db4) in comodo.comfollow up this md5sum(f521ab4944bdb4f2d9bdc91c8bbd34ca)follow up this itemfollow up this virusname (Trojan.Win32.Alureon%21IK) as RSS-Feedfollow up this malware(Trojan.Win32.Alureon%21IK) for scanner (a_squared) in md5 table15/41 (36.59%) Trojan.Win32.Alureon!IK
Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/540_2.exe  up Saved evidence (62464 Bytes) of first contact as txt December 08 2009 09:26:50 CET.No evidence recorded deadSaved log of last contact as txt December 18 2009 07:26:10 CET. SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(ip) in same window 89.248.162.164 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(review) in same window 89.248.162.164 Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/540_2.exe follow up this domain(guardericals.in) guardericals.in follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns3.eu.editdns.net follow up this item ns4.eu.editdns.net follow up this item ns4.us.editdns.net follow up this item ns5.us.editdns.net follow up this item ns6.us.editdns.net Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/540_2.exe
44 302180 2009-12-08 09:17:39 2009-12-18 07:26:10 238.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt December 08 2009 10:18:55 CET.15/41 (36.59%) 
 Virustotal.
MD5:
f521ab4944bdb4f2d9bdc91c8bbd34ca
Trojan.Inject.alxc
a
variant
of
Win32/Kryptik.BFO
Trojan.Generic.2823013
 
 lookup in virustotal.com (f521ab4944bdb4f2d9bdc91c8bbd34ca)-->[http://www.virustotal.com/analisis/f24be0d0013fea154b30cf15df068f3b939d494ff236237ae91f175add1b8db4-1260216729]lookup in threatexpert.comlookup the sha256(f24be0d0013fea154b30cf15df068f3b939d494ff236237ae91f175add1b8db4) in comodo.comfollow up this md5sum(f521ab4944bdb4f2d9bdc91c8bbd34ca)follow up this itemfollow up this virusname (Trojan.Win32.Alureon%21IK) as RSS-Feedfollow up this malware(Trojan.Win32.Alureon%21IK) for scanner (a_squared) in md5 table15/41 (36.59%) Trojan.Win32.Alureon!IK
Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/541_2.exe  up Saved evidence (62464 Bytes) of first contact as txt December 08 2009 09:26:44 CET.No evidence recorded deadSaved log of last contact as txt December 18 2009 07:26:09 CET. SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(ip) in same window 89.248.162.164 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(review) in same window 89.248.162.164 Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/541_2.exe follow up this domain(guardericals.in) guardericals.in follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns3.eu.editdns.net follow up this item ns4.eu.editdns.net follow up this item ns4.us.editdns.net follow up this item ns5.us.editdns.net follow up this item ns6.us.editdns.net Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/541_2.exe
45 302181 2009-12-08 09:17:39 2009-12-18 07:26:09 238.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt December 08 2009 10:19:05 CET.15/41 (36.59%) 
 Virustotal.
MD5:
f521ab4944bdb4f2d9bdc91c8bbd34ca
Trojan.Inject.alxc
a
variant
of
Win32/Kryptik.BFO
Trojan.Generic.2823013
 
 lookup in virustotal.com (f521ab4944bdb4f2d9bdc91c8bbd34ca)-->[http://www.virustotal.com/analisis/f24be0d0013fea154b30cf15df068f3b939d494ff236237ae91f175add1b8db4-1260216729]lookup in threatexpert.comlookup the sha256(f24be0d0013fea154b30cf15df068f3b939d494ff236237ae91f175add1b8db4) in comodo.comfollow up this md5sum(f521ab4944bdb4f2d9bdc91c8bbd34ca)follow up this itemfollow up this virusname (Trojan.Win32.Alureon%21IK) as RSS-Feedfollow up this malware(Trojan.Win32.Alureon%21IK) for scanner (a_squared) in md5 table15/41 (36.59%) Trojan.Win32.Alureon!IK
Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/545_2.exe  up Saved evidence (62464 Bytes) of first contact as txt December 08 2009 09:26:41 CET.No evidence recorded deadSaved log of last contact as txt December 18 2009 07:26:09 CET. SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(ip) in same window 89.248.162.164 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(review) in same window 89.248.162.164 Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/545_2.exe follow up this domain(guardericals.in) guardericals.in follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns3.eu.editdns.net follow up this item ns4.eu.editdns.net follow up this item ns4.us.editdns.net follow up this item ns5.us.editdns.net follow up this item ns6.us.editdns.net Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/545_2.exe
46 302182 2009-12-08 09:17:39 2009-12-18 07:26:09 238.1 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt December 08 2009 10:19:15 CET.15/41 (36.59%) 
 Virustotal.
MD5:
f521ab4944bdb4f2d9bdc91c8bbd34ca
Trojan.Inject.alxc
a
variant
of
Win32/Kryptik.BFO
Trojan.Generic.2823013
 
 lookup in virustotal.com (f521ab4944bdb4f2d9bdc91c8bbd34ca)-->[http://www.virustotal.com/analisis/f24be0d0013fea154b30cf15df068f3b939d494ff236237ae91f175add1b8db4-1260216729]lookup in threatexpert.comlookup the sha256(f24be0d0013fea154b30cf15df068f3b939d494ff236237ae91f175add1b8db4) in comodo.comfollow up this md5sum(f521ab4944bdb4f2d9bdc91c8bbd34ca)follow up this itemfollow up this virusname (Trojan.Win32.Alureon%21IK) as RSS-Feedfollow up this malware(Trojan.Win32.Alureon%21IK) for scanner (a_squared) in md5 table15/41 (36.59%) Trojan.Win32.Alureon!IK
Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/546_2.exe  up Saved evidence (62464 Bytes) of first contact as txt December 08 2009 09:26:35 CET.No evidence recorded deadSaved log of last contact as txt December 18 2009 07:26:09 CET. SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(ip) in same window 89.248.162.164 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(review) in same window 89.248.162.164 Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/546_2.exe follow up this domain(guardericals.in) guardericals.in follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns3.eu.editdns.net follow up this item ns4.eu.editdns.net follow up this item ns4.us.editdns.net follow up this item ns5.us.editdns.net follow up this item ns6.us.editdns.net Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/546_2.exe
47 301085 2009-12-06 16:46:00 2009-12-18 08:00:23 279.2 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt December 06 2009 20:22:37 CET.1/40 (2.50%) 
 Virustotal.
MD5:
e85a0afa55ce52e5b77b8efc2d31bfbe
Backdoor.Win32.Bredolab.bdu
 
 lookup in virustotal.com (e85a0afa55ce52e5b77b8efc2d31bfbe)-->[http://www.virustotal.com/analisis/31c70298c08ad9eb60e5b6cd246f086020bdae7e917be129294b0b6859bd465f-1260008353]lookup in threatexpert.comlookup the sha256(31c70298c08ad9eb60e5b6cd246f086020bdae7e917be129294b0b6859bd465f) in comodo.comfollow up this md5sum(e85a0afa55ce52e5b77b8efc2d31bfbe)follow up this itemfollow up this virusname (Backdoor.Win32.Bredolab.bdu) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(Backdoor.Win32.Bredolab.bdu) for scanner (Kaspersky) in md5 table1/40 (2.50%) Backdoor.Win32.Bredolab.bdu
Safe Virus-Viewer and Analyser may take a minute to complete http://cammaru.cn/cp/tasksz.php?load=5f4 ...  up Saved evidence (34828 Bytes) of first contact as txt December 06 2009 18:29:50 CET.No evidence recorded deadSaved log of last contact as txt December 18 2009 08:00:23 CET. SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(ip) in same window 89.248.162.164 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(review) in same window 89.248.162.164 Safe Virus-Viewer and Analyser may take a minute to complete http://cammaru.cn/cp/tasksz.php?load=5f4 ... follow up this domain(cammaru.cn) cammaru.cn follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item free01.editdns.net follow up this item free02.editdns.net follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://cammaru.cn/cp/tasksz.php?load=5f4 ...
48 299207 2009-12-04 00:00:00 2009-12-06 13:14:38 61.2 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Fragus+Exploit+Pack) as RSS-Feedfollow up this malware(malwareurl_Fragus+Exploit+Pack) for scanner () in md5 table malwareurl_Fragus Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/in.php  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt December 06 2009 13:14:38 CET. SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(ip) in same window 89.248.162.164 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(review) in same window 89.248.162.164 Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/in.php follow up this domain(guardericals.in) guardericals.in follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns3.eu.editdns.net follow up this item ns4.eu.editdns.net follow up this item ns4.us.editdns.net follow up this item ns5.us.editdns.net follow up this item ns6.us.editdns.net Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/in.php
49 299208 2009-12-04 00:00:00 2009-12-06 13:14:38 61.2 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Fragus+Exploit+Pack) as RSS-Feedfollow up this malware(malwareurl_Fragus+Exploit+Pack) for scanner () in md5 table malwareurl_Fragus Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/1.swf  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt December 06 2009 13:14:38 CET. SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(ip) in same window 89.248.162.164 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(review) in same window 89.248.162.164 Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/1.swf follow up this domain(guardericals.in) guardericals.in follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns3.eu.editdns.net follow up this item ns4.eu.editdns.net follow up this item ns4.us.editdns.net follow up this item ns5.us.editdns.net follow up this item ns6.us.editdns.net Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/1.swf
50 299209 2009-12-04 00:00:00 2009-12-18 08:25:44 344.4 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
lookup in anubis17/40 (42.50%) 
 Virustotal.
MD5:
8d499308df04932ed1b58a78417d6fb9
Trojan
Horse
Java.OpenStream.AD
Trojan.Generic.IS.614610
 
 lookup in virustotal.com (8d499308df04932ed1b58a78417d6fb9)-->[http://www.virustotal.com/de/reanalisis.html?eb4f3bd460824c701f3a99463a16e4307f5a4c111f1dc610d26db82d6436f842-1272281499]lookup in threatexpert.comlookup the sha256(eb4f3bd460824c701f3a99463a16e4307f5a4c111f1dc610d26db82d6436f842) in comodo.comfollow up this md5sum(8d499308df04932ed1b58a78417d6fb9)follow up this itemfollow up this virusname (JAVA%2FOpenStream.AD) as RSS-Feedfollow up this malware(JAVA%2FOpenStream.AD) for scanner (AntiVir) in md5 table17/40 (42.50%) JAVA/OpenStream.AD
Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/etc/2008-5353.j ...  up Saved evidence (4519 Bytes) of first contact as txt November 08 2009 23:10:53 CET.No evidence recorded deadSaved log of last contact as txt December 18 2009 08:25:44 CET. SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(ip) in same window 89.248.162.164 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29073) in networks tablefollow up this itemfollow up this AS (AS29073) as RSS-Feed AS29073 SenderBaselookup 89.248.162.164 at Rus CERT university stuttgart germanylookup 89.248.162.164 at Ripefollow up this item(review) in same window 89.248.162.164 Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/etc/2008-5353.j ... follow up this domain(guardericals.in) guardericals.in follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@ecatel.net) as RSS-Feed abuse@ecatel.net follow up this itemfollow up this item 89.248.162.128 - 89.248.162.255 follow up this item NL-ECATEL follow up this item AS29073, Ecatel LTDAS29073, Route object follow up this item ns3.eu.editdns.net follow up this item ns4.eu.editdns.net follow up this item ns4.us.editdns.net follow up this item ns5.us.editdns.net follow up this item ns6.us.editdns.net Safe Virus-Viewer and Analyser may take a minute to complete http://guardericals.in/q/etc/2008-5353.j ...
Click here for other vital incidents